International · English
An overview of DPO and equivalent roles in key jurisdictions, and of how we support organisations operating internationally.
Many jurisdictions outside the European Union now require a Data Protection Officer or an equivalent role, although the trigger, the title and the responsibilities differ. The summary below reflects the position known at the date of this page.
The UK GDPR and the Data Protection Act 2018 keep DPO requirements equivalent to those of the EU GDPR, under the supervision of the Information Commissioner's Office. The Data (Use and Access) Act 2025 did not change the DPO requirement.
The revised Federal Act on Data Protection, in force since September 2023, makes the data protection advisor optional for private controllers. Appointing one allows a controller to consult the advisor, instead of the Federal Data Protection and Information Commissioner, on a high-risk impact assessment. Federal bodies must appoint an advisor.
The LGPD requires controllers to appoint an encarregado, with an exemption for small processing agents. See the offers for Brazil.
Under the Protection of Personal Information Act, the head of a private body is its Information Officer by default, and deputies may be designated. Information Officers must be registered with the Information Regulator.
The Personal Data Protection Act requires every organisation to designate at least one individual to be responsible for ensuring compliance, commonly called the DPO, and to make that individual's business contact information available.
The Personal Information Protection Law requires a personal information protection officer where the volume of personal information processed reaches the threshold set by the Cyberspace Administration of China, currently the personal information of more than one million individuals.
The Digital Personal Data Protection Act 2023 is implemented by the rules notified in November 2025, with phased application. Significant Data Fiduciaries must appoint a DPO based in India, with that obligation applying from May 2027.
For organisations operating across several of these jurisdictions, we build a privacy programme on a GDPR-grade baseline and adapt it to each local regime. The baseline can be aligned with ISO/IEC 27701:2025, now a standalone privacy information management system standard, to support certification where useful.
multi-jurisdiction assessment: a map of the obligations that apply in each country;
common programme: policies, records and procedures on a single baseline;
DPO or equivalent role: designation where required and a voluntary function where not;
international transfers: a framework for data flows between the EU and other jurisdictions.
See also: European Union · Países da CPLP · Iberoamérica
General information as at October 2026; laws in these jurisdictions change frequently and must be confirmed case by case. It does not constitute legal advice.
Request a proposal tailored to the countries where your organisation operates.